Integrations: SIEM, tools and chat
Prism can send each event to your own systems as it’s decided, and lets SIEMs collect events themselves. Set it up in the Prism console under Integrations (admins). Only redacted data ever leaves Prism: detected values are replaced by placeholders such as [AWS_KEY_1], and the text is left out entirely unless you switch on Include redacted text for a destination. Chat alerts never carry content.
Each destination chooses what it receives: Blocked only, Warned and blocked (the default for SIEMs and webhooks), Everything, and optionally Admin changes (the audit log). Prism retries a destination that’s down for about a day, and switches it off after three days of failures; the console shows its state and last error. Send a test delivers a test message straight away.
The event format (prism.event.v1)
{
"schema": "prism.event.v1",
"id": "8f0c…",
"time": "2026-10-09T12:00:00.000Z",
"received_at": "2026-10-09T12:00:00.412Z",
"user": { "email": "li@acme.com", "name": "Li Ortiz" },
"sensor": "browser",
"action": "send",
"destination": { "app": "chatgpt.com", "tool": "web:chatgpt", "account": "personal" },
"verdict": "deny",
"applied": "block",
"mode": "block",
"severity": "critical",
"reasons": ["HARD_DETECTOR", "CREDENTIAL_EXPOSURE"],
"detections": [{ "type": "aws_access_key", "category": "credentials", "severity": "critical", "count": 1 }],
"content": { "size": 86, "filename": null, "text": "Can you check why this fails: … [AWS_KEY_1]" },
"console_url": "https://app.prism-dlp.com/incidents/8f0c…"
}
action:paste,upload,send(a typed message) orcopy(Mac agent: USB and cloud folders).verdictis Prism’s decision (allow,coach,deny,review);appliedis what happened under your enforcement mode (allow,allow_logged,coach,block). In observe mode adenyis applied asallow_logged.detections: what Prism found. Built-in detectors have atypesuch asaws_access_key; your own detectors arecustom:<id>with theirname.content.textis present only when the destination includes redacted text.- Admin changes use
prism.audit.v1:id,time,actor,action(for exampleverdict.override,settings.update,integration.create),target,detail.
Webhooks
Prism sends POST with a JSON body { "type": "prism.event" | "prism.audit" | "prism.test", "timestamp": "…", "data": { … } }, signed the Standard Webhooks way:
webhook-id: unique per message and the same on every retry (use it to drop duplicates)webhook-timestamp: Unix secondswebhook-signature:v1,<base64 HMAC-SHA256 of "{id}.{timestamp}.{body}">, keyed with yourwhsec_…secret (base64 after the prefix)
The signing secret is shown once when you add the webhook. Verify with any Standard Webhooks library, for example in Node:
import { Webhook } from "standardwebhooks";
const wh = new Webhook(process.env.PRISM_WEBHOOK_SECRET); // whsec_…
const event = wh.verify(rawBody, request.headers); // throws if the signature or timestamp is wrong
Reply with any 2xx status within 10 seconds. Prism doesn’t follow redirects, and only sends to public https:// addresses.
Splunk
- In Splunk, go to Settings → Data inputs → HTTP Event Collector, then New Token.
- Name it Prism DLP, click Next, pick the index Prism should write to (and allow it), then Review → Submit.
- Copy the Token Value.
- In Prism, Integrations → Add Splunk: the URL is your HEC address (Splunk Cloud:
https://http-inputs-<stack>.splunkcloud.com, where<stack>is the first part of your Splunk Cloud address; Splunk Enterprise:https://<host>:8088), the token, and the same index. - Add destination, then Send a test, and search Splunk for
sourcetype="prism:event"orsource="prism-dlp".
Events arrive with sourcetype=prism:event (audit: prism:audit) unless you set your own; the event body is the format above. Splunk Enterprise must be reachable from the internet over https with a publicly trusted certificate, with HEC switched on under Global Settings.
Slack
Add to Slack (one click): in Prism, Integrations → Add Slack → Add to Slack. Slack asks which channel Prism DLP may post to: pick it and click Allow. You come back to Prism with the destination added and a test message in the channel. If Slack says the app needs approval, your workspace only lets admins add apps: ask a Slack admin to approve Prism DLP.
Or paste a webhook URL (choose “Paste a webhook URL instead” in Prism):
- In Slack, create or pick the channel for alerts, for example
#security-alerts. - In Prism, go to Integrations → Add Slack and click Create the Slack app. Slack opens with Prism’s settings already filled in: pick your workspace, then Next, then Create.
- Click Install to Workspace. Under “Where should Prism DLP post?” choose your channel, then Allow. (If Slack says the app needs approval, ask a Slack admin to do these steps.)
- If you see “Prism DLP is ready!” with Slack CLI commands, ignore them and click Go to App Settings.
- In the left sidebar, under Features, click Incoming Webhooks. Under “Webhook URLs for Your Workspace”, click Copy next to your channel. (Empty list? Add New Webhook, pick the channel, Allow.)
- Back in Prism, paste the URL, click Add destination, then Send a test. A test message appears in the channel.
Alerts say what happened, who, where and what was found, with a link to the event in Prism. Chat destinations default to Blocked only and never include content.
Microsoft Teams
- In Teams, open the channel for alerts, click ••• (More options) next to its name, then Workflows.
- Search for webhook and choose Post to a channel when a webhook request is received.
- Name it Prism DLP, click Next, check the team and channel, then Add workflow.
- Copy the URL Teams shows, then Done.
- In Prism, Integrations → Add Microsoft Teams, paste the URL, Add destination, then Send a test. A card appears in the channel.
The workflow belongs to whoever creates it and stops if their account is removed, so use a shared or service account. (Microsoft retired the older Office 365 connector webhooks.)
Events API (for SIEMs that collect)
Create a read key in the console under Set up (read keys can only read; sensor keys can’t read). Then:
GET https://api.prism-dlp.com/v1/export/events?events=flagged&limit=200
Authorization: Bearer pk_…
The response is { "data": [ …events… ], "next_cursor": "…" }. Pass cursor=<next_cursor> on the next call; keep the last cursor as your checkpoint, and an empty data means you’re up to date. Events appear about 10 seconds after they happen, so a poll never skips one that was still being saved.
events:all(default),flagged(warned, blocked, needs review) orblockedlimit: 1–1000 (default 200)include_text=true: add the redacted textGET /v1/export/audit: the audit log, samecursorandlimit- Rate limit: about 10 requests a second per key (HTTP 429 with
retry-afterbeyond that)
Microsoft Sentinel
Until a ready-made Sentinel connector is available:
- In Azure, create a custom table (for example
PrismDLP_CL) and a data collection rule for it, and an Entra app registration with the Monitoring Metrics Publisher role on the rule (Logs Ingestion API). - Create a Logic App with the trigger “When an HTTP request is received”, and an action that sends the request body’s
datato the rule’s stream (Custom-PrismDLP_CL). - In Prism, add a Webhook with the Logic App’s trigger URL.
Alternatively, collect from the Events API with an Azure Function on a timer.
Updated 9 October 2026